View Single Post
Old 07-10-2008, 12:37 AM   #12 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,318
OS: XP SP3


Re: Winspyware Hijacks my desktop and screen saver

Hi,

Thanks for the screenshots. It appears that those tools were able to clean most of the infection.
Quote:
also screen shots of the list of things that Avant found since this started
I guess you mean Avast.

Quote:
C:\WINDOWS\Downloaded Program Files\WONWebLauncherControl.ocx

Not finding that file exactly as you posted it

There is this file in that folder
WONWebLauncher Class
Quote:
I have a questioin or two. The WonWebLauncher is I believe how I get to a web site the old Hoyle site to play cards... bein playen cards there for 10 years. The Hoyle CD has been discontinued and the site certificate is out of date. I have to roll my system clock back to 2005 in order to get in the rooms there. Back in the day WON used to have ads that ran across the tops of the rooms but that is not the case any longer. It does install some things but I haven't seen an ad since Cases Ladder started running the site a couple of years ago.
WONWebLauncherControl.ocx was reported by Kaspersky as an adware.

Quote:
C:\WINDOWS\Downloaded Program Files\WONWebLauncherControl.ocx Infected: not-a-virus:AdWare.Win32.IWon.c skipped
So, it's up to you to keep or delete WONWebLauncherControl class.

=============================

Quote:
Privacy Protection was listed under Web tab and I unticked it. Thats all that was there
That was the cause of the white background and it was caused by malware. Did you restart your computer afterwards?

=============================

You can go ahead and delete the fixreg.reg file from your desktop now.

=============================
Quote:
Also could you tell me what was causing that ScreenSaver tab to dissappear on the Display screen ?
Also caused by malware which you seemed to have downloaded while downloading some games. I don't know where you downloaded them from but most likely via p2p file sharing programs. I would like to take this opportunity to warn you that the nature of P2P filesharing is so that even if one is using a "clean" program, many of the files downloaded from non-documented sources have the potential of being infected. So, regardless of whether one is using a "clean" program, one may still be prone to infection by malware because more than half of all files available for download from peer-to-peer networks have been deliberately infected with some form of malware. Also by default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple, file sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft.
I recommend very strongly that you remove any file sharing program you may have from your system via Add/Remove Programs in Control Panel.

==============================

You either didn't run the Symantec Removal tool or the tool didn't remove the leftovers. Please do the following, one at a time, to remove those remnants:

Go to Start > Run. Copy/Paste the text in blue, including the quote marks where present:

sc stop "Automatic LiveUpdate Scheduler" and then click OK
sc stop LiveUpdate and then click OK
sc stop SNDSrvc and then click OK

sc delete SNDSrvc and then click OK
sc delete LiveUpdate and then click OK
sc delete "Automatic LiveUpdate Scheduler" and then click OK

=============================

In my last fix I missed one bad registry entry that was disabled via msconfig.

Open notepad. It must be notepad, not wordpad.
Copy and paste the text inside the code box below into notepad, including the blank line at the end. Make sure that wordwrap is turned off in notepad - click the format menu and uncheck wordwrap.
Choose file save as and set file type to all files.
Type amendreg.reg in the file name and save it to your desktop. It should look like this:

Quote:
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSpywareProtect]

[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Close notepad. Make sure that all windows are closed.

Find the amendreg.reg file on your desktop.
Double click it.
It will then ask if you want the file merged to your registry.
Answer yes.

================================

Reboot your computer. (it's important)

================================

Post a fresh HijackThis log please.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline